Security Engineer

Posted 2 Days Ago
Be an Early Applicant
McLean, VA, USA
In-Office
150K-200K Annually
Senior level
Security • Cybersecurity
The Role
Lead FedRAMP/IC ATO and RMF lifecycle activities, conduct risk and security control assessments, manage vulnerability and continuous monitoring programs, integrate security into cloud and DevSecOps pipelines, support incident response and audits, maintain security documentation, and advise/mentor teams on compliance and secure architecture for government cloud and classified environments.
Summary Generated by Built In

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

Clearance Required: Active TS/SCI with Polygraph

Summary

We are seeking a Senior Security Engineer to support cybersecurity operations, compliance, and risk management for FedRAMP-authorized and Intelligence Community (IC) systems. This role is responsible for ensuring systems meet stringent federal security requirements while enabling secure, scalable, and compliant cloud and on-premises solutions.

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), cloud security, incident response, and ATO lifecycle management, along with the ability to operate effectively within classified and high-security environments.

The Senior Security Engineer serves as the primary cybersecurity technical authority supporting system engineering, cloud architecture, DevSecOps pipelines, compliance initiatives, and operational security monitoring.

Key Responsibilities

  • Lead and support FedRAMP Moderate/High and IC ATO authorization efforts, ensuring compliance with NIST RMF, NIST 800-53, NIST 800-37, FedRAMP, and ICD 503 requirements.
  • Conduct risk assessments, security control assessments, gap analyses, and security architecture reviews to identify and mitigate cybersecurity risks.
  • Manage the full Risk Management Framework (RMF) lifecycle, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain security documentation such as SSPs, SARs, POA&Ms, and control traceability artifacts, while tracking remediation activities.
  • Execute Continuous Monitoring (ConMon) programs through vulnerability assessments, compliance reviews, security control validation, and reporting.
  • Lead vulnerability management activities using tools such as Nessus, ACAS, SCAP, and STIG Viewer, validating remediation and coordinating risk mitigation efforts.
  • Support Security Operations and Incident Response, including threat monitoring, alert analysis, incident investigations, root cause analysis, and coordination with SOCs and government stakeholders.
  • Design and assess security controls for AWS GovCloud, Azure Government, and other government cloud environments, implementing IAM, encryption, logging, and least-privilege access controls.
  • Integrate security into DevSecOps and CI/CD pipelines through automated security testing, vulnerability scanning, compliance validation, and Infrastructure-as-Code security practices.
  • Support audits and assessments, including 3PAO reviews, FedRAMP assessments, agency ATO reviews, and IG audits, while preparing evidence and coordinating with auditors and assessors.
  • Administer and utilize governance, compliance, monitoring, and vulnerability management tools such as ServiceNow GRC, Splunk, and Azure.
  • Collaborate with developers, engineers, cloud architects, ISSOs/ISSMs, compliance teams, and government stakeholders to provide cybersecurity guidance throughout system development and operations.
  • Contribute to security governance, policy development, cybersecurity program maturity, and organizational security culture, while mentoring junior staff and promoting risk-informed decision-making.

Required Qualifications 

  • Active TS/SCI with Polygraph
  • Bachelor's degree or higher in Cybersecurity, IT, or related field and 5+ years' experience in Cybersecurity in federal or IC environments
  • OR Masters and 3+ years of experience in Cybersecurity in federal or IC environments
  • Strong Knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • At least one of the following certifications: CISM or CISA, CompTIA Security+ (baseline), Certified Authorization Professional (CAP), CCSP (cloud security)
  • Experience in the following tools: NIST 800-53, RMF, FedRAMP, ICD 503, ServiceNow GRC, Splunk, AWS GovCloud, Azure 

Desired Qualifications

  • Experience with cloud-native security tools
  • Knowledge of Zero Trust Architecture
  • Experience with cross-domain solutions
  • Familiarity with DevSecOps pipelines in regulated environments

Salary Range: $150,000 - $200,000

The pay range reflected above is a general guideline for this position and labor category and is not a guarantee of a specific salary or offer. Final compensation is determined based on factors including, but not limited to, relevant experience, education, certifications, security clearance level, contract requirements, geographic location, and internal pay equity, and may reflect market data specific to the awarded contract.


Core One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

__PRESENT

__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT

Skills Required

  • Active TS/SCI with Polygraph
  • Bachelor's degree in Cybersecurity, IT, or related field and 5+ years cybersecurity experience in federal or IC environments OR Master's degree and 3+ years experience in federal or IC environments
  • Strong knowledge of NIST RMF (800-37), NIST 800-53 controls, and FedRAMP requirements
  • Experience supporting FedRAMP Moderate/High and IC ATO authorization efforts and RMF lifecycle management
  • Experience with ServiceNow GRC, Splunk, AWS GovCloud, and Azure
  • Experience with vulnerability management tools such as Nessus, ACAS, SCAP, and STIG Viewer
  • At least one of the following certifications: CISM, CISA, CompTIA Security+, Certified Authorization Professional (CAP), or CCSP
  • Experience integrating security into DevSecOps/CI-CD pipelines and Infrastructure-as-Code security practices
  • Ability to perform security documentation (SSPs, SARs, POA&Ms) and support 3PAO/FedRAMP/agency assessments
  • Experience operating within classified and high-security government environments and coordinating with ISSOs/ISSMs and government stakeholders
  • Experience with continuous monitoring (ConMon), vulnerability assessments, compliance reviews, and incident response in regulated environments
  • Experience with cloud security controls for AWS GovCloud and Azure Government (IAM, encryption, logging, least privilege)
  • Experience with cloud-native security tools (Desired)
  • Knowledge of Zero Trust Architecture (Desired)
  • Experience with cross-domain solutions (Desired)
  • Familiarity with DevSecOps pipelines in regulated environments (Desired)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sterling, VA
61 Employees

What We Do

Our mission is to be at the forefront of devising analytical, operational and technical solutions to the most complex national security challenges by delivering superior advice, building trusted partnerships, and augmenting the capabilities of our clients.

Similar Jobs

CDW Logo CDW

Security Engineer

Information Technology
Remote or Hybrid
US
15100 Employees
133K-193K Annually

Applied Systems Logo Applied Systems

Security Engineer

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3079 Employees
80K-120K Annually

MongoDB Logo MongoDB

Security Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
3 Locations
5550 Employees
106K-209K Annually

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
160K-250K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account